Release automation

Ship on Friday.
Roll back in seconds.

Capstan turns your deploy scripts into one readable pipeline with gates, approvals, and an eleven-second rollback.

A release plotted as stacked translucent layers, each edge lit in green, representing the stages of a deploy pipeline.

Trusted by engineering teams at

  • Northgate
  • Kestrel Labs
  • Tidewater
  • Halberd
  • Pinemark
  • Quarry Systems

What release teams see in the first month

Deploys coordinated
4.8M

across 1,240 production services in the last year

Median rollback
11s

from the first alert to production running the last good artifact

Deploy frequency
3.1x

more releases per week by the end of month one

Pipeline availability
99.98%

measured over the last four quarters, including incidents

Three moves, every release.

No rewrite. Capstan reads what you already run, then adds the parts every team ends up building by hand.

  1. Connect

    Point Capstan at your repo and your cloud account. It maps your existing shell targets and Makefiles into ordered stages.

  2. Gate

    Choose what has to pass before production moves: test suites, a migration dry run, an approval from the service owner.

  3. Ship

    Promote the release, watch the live diff roll out per region, and send production back to the last good artifact in one click.

Built for the parts of shipping that hurt.

Release diff

Every release shows exactly which services, migrations, and environment variables changed, before anyone approves it.

Two engineers working at a long desk by a window at dusk.

On-call handoff

The next shift opens one page and sees what shipped, what is gated, and what is still rolling out.

Feature flags

Flags and deploys share one approval path, so nothing ships twice or slips out behind an old branch.

Audit trail

Every approval, override, and rollback is recorded with who did it and what they wrote down at the time.

Instant rollback

Eleven-second median. No git archaeology at 2am, and no rebuilding an artifact that already existed an hour ago.

We went from two deploys a week to forty. The pipeline stopped being a secret.

Marta Kowalczyk Director of Platform Engineering, Tidewater

Pricing

Priced per service, not per seat.

Add every engineer you have. We only count the services you deploy.

Solo

$0forever

One service, unlimited deploys, and the full CLI.

  • 1 production service
  • Unlimited deploys and rollbacks
  • Community support
Start free

Enterprise

Custom

For regulated teams running their own infrastructure.

  • SSO and SCIM provisioning
  • Private runners in your VPC
  • On-prem control plane
  • Named solutions engineer
Talk to sales

Every plan includes the CLI, the API, and rollback. No per-minute runner billing.

Questions we get on the first call.

Does Capstan replace our CI?

No. Capstan sits after CI. Your tests keep running wherever they run today; Capstan decides what happens once they pass and records the result against the release.

What if our deploy is a script someone wrote in 2019?

That is the normal starting point. Capstan reads existing shell and Makefile targets and maps them into stages, so the first pipeline does not require rewriting anything.

How does rollback actually work?

Capstan records the exact artifact each release points at. Rolling back re-points production at the last good artifact and replays any migrations that were marked reversible.

Can approvals stay in Slack?

Yes. Approvals, rejections, and rollback confirmations can all be handled from Slack, writing the same audit record as the web interface.

Where does Capstan run?

The control plane is hosted in the US or the EU. Deploy runners execute inside your own cloud account, so artifacts and secrets never leave your network.

Ship on Friday.

Start with one service. Add the rest when it works.

Start free